CVE Published: 19/04/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: Eaton |
Vendor: Eaton |
Product: Eaton Intelligent Power Protector (IPP) Status : PUBLISHED
CVE-2021-23283 Description
Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding of the output for certain resources within the IPP software.
Metrics
CVSS Version: 3.1 |
Base Score: 5.2 MEDIUM Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H